<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Move zone and policies between VSYS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/218975#M63268</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13566"&gt;@licenselu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Because of the way that the firewall actually handles VSYS you can't actually move it between VSYS directly in the GUI; because that kind of ruins the whole point of VSYS being a totally seperate virtual System. What you can do, and what I would recommend in this situation, is moving the policies directly through the XML or the Migration Tool by simply cutting the code from one VSYS location and copying it the next.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a word of caution in how you are doing this currently; I've found companies that implement with the design of moving to a multi VSYS configuration once the firewall is already processing traffic, it never actually happens. I would highly recommend pushing them to allow you to do the configuration of the multiple VSYS before the firewall is actually in production. This design simply duplicates a lot of work regardless of how you actually make this change once it's been put in place.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jun 2018 18:47:47 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-06-22T18:47:47Z</dc:date>
    <item>
      <title>Move zone and policies between VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/218848#M63235</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of our customer wants to implement VSYS. Currently, the current firewall is Checkpoint appliance (around 900 rules)..&lt;/P&gt;&lt;P&gt;The idea is to replicated the config from the Checkpoint to the PA with only one VSYS to avoid a big bang...&lt;/P&gt;&lt;P&gt;So I will create all zone (in the only one VSYS in the beginning) and policy between zone.&lt;/P&gt;&lt;P&gt;Until now, everything is OK...&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The next phase will be to the divide the initial VSYS to 3 or 4 VSYS (only on routing table for all VSYS).&lt;/P&gt;&lt;P&gt;It seems it's not possible to move zone (and thus policies) between VSYS (interface/subinterface can be moved) when its' created...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So does it mean I need to recreate zone and policies in the new VSYS ?&lt;/P&gt;&lt;P&gt;PS: I known that the destination zone will change because the destination zone will be in another VSYS...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Any idea to eliminate the needs to recreate zone and policies and to avoid granular rulebase review everytime we add a new VSYS...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 13:21:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/218848#M63235</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2018-06-22T13:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Move zone and policies between VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/218975#M63268</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13566"&gt;@licenselu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Because of the way that the firewall actually handles VSYS you can't actually move it between VSYS directly in the GUI; because that kind of ruins the whole point of VSYS being a totally seperate virtual System. What you can do, and what I would recommend in this situation, is moving the policies directly through the XML or the Migration Tool by simply cutting the code from one VSYS location and copying it the next.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a word of caution in how you are doing this currently; I've found companies that implement with the design of moving to a multi VSYS configuration once the firewall is already processing traffic, it never actually happens. I would highly recommend pushing them to allow you to do the configuration of the multiple VSYS before the firewall is actually in production. This design simply duplicates a lot of work regardless of how you actually make this change once it's been put in place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 18:47:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/218975#M63268</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-22T18:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Move zone and policies between VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/219070#M63281</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, thanks a lot for your reply.&lt;/P&gt;&lt;P&gt;What's do you mean by 'it never actually happens' ??&lt;/P&gt;&lt;P&gt;Is it not enough to reboot the firewall (after moving the interface to the correct VSYS') ??&lt;/P&gt;&lt;P&gt;In my case, a maintenance window will be available to perform such kind of operations...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 06:18:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/219070#M63281</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2018-06-25T06:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: Move zone and policies between VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/219112#M63289</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13566"&gt;@licenselu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What I meant was that when companies attempt to setup the configuration with a single VSYS to get everything functional with minimal changes with the intent to eventually switch to a multi-VSYS setup, they hardly ever actually make it to a multi-VSYS deployment. Once you have a working system in production moving to a multi-VSYS deployment is the steps to move the configuration over to a multi-VSYS and update the routing and security policies appropriately is a lot of work, with a large possibility of downtime as you work through any issues that may arise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 13:59:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/move-zone-and-policies-between-vsys/m-p/219112#M63289</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-25T13:59:11Z</dc:date>
    </item>
  </channel>
</rss>

